---
title: Privacy Options in Profile
slug: portal-sub/privacy-options-in-profile
docTags: 
createdAt: 2026-03-04T12:03:15.447Z
---

Privacy options in Profile keep track of a user’s permissions based on the configuration settings and any additional settings applied via macro. This means that System Administrators have a high level of control over what gets displayed to which user.  Available options are:

### 1. Role Actions is the first line of defense in Profile for privacy and should be the basis of your access model

- Set roles to allow users to see the toolbars, views, actions and the parts of the medical record they should see
- Configure different settings for users at different Places-of-Service (POS)

**2. Notable Person&#xA0;**&#x6C;et's you 'flag' the patients who are notable figures e.g. actors, VIPs, etc..

- Available as a preference on a patient’s record
- Usable in conjunction with other privacy settings; used on its own it will not trigger any actions
- Ensures that users of the EMR are not viewing the patient’s information without a valid reason

**3. Privacy Alert&#xA0;**&#x6C;ets the user who is opening the medical record know that there is data that they cannot see.

- Helps keep duplicate information from being created
- Use with caution because even the flag indicating there is information the clinician cannot see may be a privacy problem, depending on the type of data.

**4. Grants and Exclusions&#xA0;**&#x62;locks access to a specific patient record by a specific individual – for instance, a relative or friend of the patient.

- Protect the record of a staff member from other staff working at a particular clinic
- Using *Access Macro* and a supplementary role also lets you set up Grants and Exclusions; base decisions on “Works At” roles or Place-of-Service (POS) membership.

**5. Anonymized Lists&#xA0;**&#x61;llows anonymization of patient information in medical condition lists (Incidence, Prevalence, Clinical Quality Indicators, Care Plan Analysis).

:::hint{type="success"}
Note: if you are an enterprise customer, these lists are not fully POS-aware; these lists will not work effectively for you 
:::

### 6. Break Glass is a fast way to access restricted EMR information by someone who does not regularly have access to the information 

- Useful when an emergency situation or when there's a need to access patient information from a different  Place-of-Service (POS)
- Use of Break Glass must be monitored as it as enables extra audit attributes in addition to the standard auditing of all access and changes.

**7. Cases&#xA0;**&#x6C;et users manage one part of the clinical record separately from the longitudinal health record

- Use explicit privacy settings to manage the case's privacy settings entirely independently of the rest of the patient’s health record
- Apply privacy settings via configuration options in the user interface, and macros for more sophisticated rules
- Watch out for any clinical risk or additional administrative overhead from using Cases

**8. Access Rights&#xA0;**&#x61;llow organizations to set access rights to data for a specific clinic e.g. a clinic can see,  but not edit / delete existing records, or create new records.

- Assign based upon the user roles or by membership in an Access Provider Group

           Extension of the data types that may have Create / Read / Write / Delete access rights assigned is being considered.

**9. Access Provider Groups&#xA0;**&#x70;rovide a more nuanced and ad-hoc management of user rights that can be achieved by Roles

- Profile has several Provider Group types including for data access rights

**10. Problem/Patient Privacy** is the second privacy field in the Problem window

- Patients can indicate how their information is to be used and shared
- Use with patient access via Accession to manage information in the Problems view; Diagnosis, Procedure, Social/Risk, Adverse Reaction, Administrative
- Using this feature without the patient who sees the problem can result in a loss of information when the patient is transferred to another provider

```javascript
NOTE: We recommend creating a comprehensive EMR privacy strategy before enabling any of these options.
```
